PT-2020-20362 · Google · Asylo
Kang Li
+3
·
Published
2020-08-12
·
Updated
2020-08-13
·
CVE-2020-8905
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Asylo versions prior to 0.6.0
Description
A buffer length validation issue allows an attacker to read unauthorized data. The
enc untrusted recvfrom function generates a return value deserialized by MessageReader and copied into three extents. The length of the third extents is controlled by external input and not verified on copy, enabling the attacker to force Asylo to copy trusted memory data into a small untrusted buffer.Recommendations
Update Asylo to version 0.6.0 or later.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asylo